Skip to content

Commit d2f149d

Browse files
davdhacsclaude
andcommitted
fix: Add update-ca-trust workaround for unprivileged containers
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
1 parent 797d40c commit d2f149d

File tree

2 files changed

+7
-2
lines changed

2 files changed

+7
-2
lines changed

image/scanner/scripts/import-additional-cas

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,4 +19,6 @@ copy_existing /usr/local/share/ca-certificates
1919
# Copy the custom trusted CA bundles injected by the Openshift Network Operator.
2020
copy_existing /etc/pki/injected-ca-trust
2121

22-
update-ca-trust extract
22+
# The -o flag is required for running as an unprivileged user in containers.
23+
# See: https://bugzilla.redhat.com/show_bug.cgi?id=2241240
24+
update-ca-trust extract -o /etc/pki/ca-trust/extracted

image/scanner/scripts/trust-root-ca

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,4 +6,7 @@ CA_PATH="/run/secrets/stackrox.io/certs/ca.pem"
66

77
# For RHEL
88
cp "${CA_PATH}" /etc/pki/ca-trust/source/anchors/root-ca.pem
9-
update-ca-trust
9+
10+
# The -o flag is required for running as an unprivileged user in containers.
11+
# See: https://bugzilla.redhat.com/show_bug.cgi?id=2241240
12+
update-ca-trust extract -o /etc/pki/ca-trust/extracted

0 commit comments

Comments
 (0)